Security Event Threat Mitigation with Generative AI Summaries
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Threat mitigation systems face complexity in integrating with multiple security-relevant subsystems, requiring unique queries for each, which is inefficient and cumbersome.
Innovation Solution
A computer-implemented method using a generative AI model and formatting script to automatically generate a summarized human-readable report from security event notifications across multiple subsystems, incorporating tools for decoding, decompression, and domain owner identification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If unique queries are formulated for each security-relevant subsystem, then information can be gathered from all subsystems, but the complexity and time required for integration increases
Solution Approach 1:
The patent implements a universal query language that can be used to query multiple different security-relevant subsystems through a single standardized interface. This allows the threat mitigation system to gather information from various subsystems (firewall, IDS, antivirus, etc.) using the same query mechanism, eliminating the need to formulate unique queries for each subsystem while maintaining complete information gathering capability
2Reliability
If multiple security-relevant subsystems are integrated, then comprehensive security monitoring is achieved, but the time required for processing notifications increases
Solution Approach 1:
The patent pre-processes and normalizes notifications from multiple security subsystems into a unified representation before they reach the threat mitigation system. This preliminary action of standardizing the notification format and extracting key information in advance reduces the processing time when the system needs to analyze and respond to security events, while still maintaining comprehensive monitoring across all subsystems
Data Source
AI summary
A computer-implemented method, computer program product and computing system for establishing connectivity with a plurality of security-relevant subsystems within a computing platform; receiving an initial notification of a security event from one of the security-relevant subsystems, wherein the initial notification includes a computer-readable language portion that defines one or more specifics of the security event; and iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification.


